Backdoor Attacks and Countermeasures on Deep Learning: A Comprehensive ReviewThanks: This version might be updated.Thanks: Y. Gao is with the School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China and Data61, CSIRO, Sydney, Australia. e-mail: yansong.gao@njust.edu.cnThanks: B. Doan is with the School of Computer Science, The University of Adelaide, Adelaide, Australia. e-mail: bao.doan@adelaide.edu.auThanks: Z. Zhang, S. Nepal are with Data61, CSIRO, Sydney, Australia. e-mail: {zhi.zhang; surya.nepal}@data61.csiro.au.Thanks: S. Ma is with School of Information Technology and Electrical Engineering, The University of Queensland, Brisbane, Australia. e-mail: slivia.ma@uq.edu.au.Thanks: J. Zhang is with the College of Computer Science and Electronic Engineering, Hunan University, Changsha, China. e-mail: zhangjiliang@hun.edu.cn.Thanks: A. Fu is with the School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China. e-mail: fuam@njust.edu.cnThanks: H. Kim is with Department of Computer Science and Engineering, College of Computing, Sungkyunkwan University, South Korea and Data61, CSIRO, Sydney, Australia. e-mail: hyoung@skku.edu.
Yansong Gao Bao Gia Doan Zhi Zhang Siqi Ma Jiliang Zhang Affiliation: Anmin Fu, Surya Nepal, and Hyoungshick Kim
Abstract
Backdoor attacks insert hidden associations or triggers to the deep learning models to override correct inference such as classification and make the system perform maliciously according to the attacker-chosen target while behaving normally in the absence of the trigger. As a new and rapidly evolving realistic attack, it could result in dire consequences, especially considering that the backdoor attack surfaces are broad. In 2019, the U.S. Army Research Office started soliciting countermeasures and launching TrojAI project, the National Institute of Standards and Technology has initialized a corresponding online competition accordingly.
原文 arXiv:2007.10760;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2007.10760v3